When AWS Was Actually Attacked: Drone Strikes Hit the Cloud
Drone strikes on AWS data centers in the UAE and Bahrain marked the first military attack on hyperscale cloud infrastructure, forcing a new kind of reckoning.

For months, every serious conversation about AWS reliability was really a conversation about software: DNS records, race conditions, automation gone wrong. On March 1, that conversation changed shape entirely. Drones struck two Amazon Web Services data centers in the United Arab Emirates directly, and a third facility in Bahrain was damaged by a strike nearby, according to CNBC's reporting. For the first time, a hyperscale cloud provider had been hit by military action, not a misconfigured deployment.
The strikes landed amid an escalating conflict in the Middle East. Iran fired a barrage of drones and missiles at Gulf states in retaliation for strikes that killed a senior Iranian leader, and Amazon's ME-CENTRAL-1 region infrastructure was caught directly in the path, as detailed in coverage from CBS News.
This time, the word "attack" was not a loose metaphor for a bad engineering night. It was literal, and it left physical damage that no software rollback could fix.
What was actually hit
Amazon confirmed that objects struck one of its UAE data centers directly, producing sparks and fire that required suppression efforts, according to a report from AOL News drawing on Amazon's own statements. A second UAE facility was also struck, while the Bahrain site sustained damage from a strike in close proximity rather than a direct hit, per Tom's Hardware. The strikes disrupted power delivery and, in places, triggered water damage from fire suppression systems on top of the initial structural harm.
Two of ME-CENTRAL-1's three availability zones, internally designated mec1-az2 and mec1-az3, were left significantly impaired, while the third zone continued operating normally, according to a detailed incident account from Data Center Knowledge. Services that depend on the region, including EC2, S3, DynamoDB, Lambda, Kinesis, CloudWatch and RDS, all reported elevated error rates and degraded availability in the hours after the strikes.
Who felt it on the ground
The disruption reached well past Amazon's own dashboards. Ride-hailing and delivery platform Careem, payments firms Alaan and Hubpay, and banking providers including ADCB and Emirates NBD all reported issues tracing back to the ME-CENTRAL-1 disruption, according to reporting from Data Center Dynamics. For a region where banking apps, government services and daily commerce increasingly run on cloud infrastructure, the strikes were not an abstract IT story. They were a Sunday when paying for groceries or hailing a car got harder.
Amazon's stock dipped roughly two percent in the aftermath, and the company told customers still operating in the region to back up their data and consider shifting workloads to alternate AWS regions while the conflict continued, a recommendation reported by BleepingComputer. That is an extraordinary thing for a cloud provider to say out loud: move your data, because we cannot promise this facility is safe.
The reckoning nobody had modeled
Cloud resilience planning has spent two decades focused on software failures, natural disasters and the occasional fiber cut. Physical attacks on data centers by a nation-state's military were treated, until now, as a scenario too extreme to plan around seriously. Reporting from Rest of World notes that the strikes have forced security researchers and cloud architects to confront a category of risk that redundancy across availability zones was never designed to absorb, because the zones themselves can be in the blast radius of the same conflict.
It is a strange symmetry with the October 2025 outage that preceded it by less than five months. That earlier crisis was a reminder that software concentration is dangerous even without an adversary. This one is a reminder that physical concentration is dangerous with one. Put together, they make the same argument twice, from opposite directions: too much of the internet depends on too few buildings, whether the threat is a bad DNS update or a drone.
What happens to Gulf cloud strategy now
Amazon has not said when the ME-CENTRAL-1 region will be fully repaired, only that recovery would be prolonged given the physical nature of the damage, and that its engineers were pursuing software-based recovery paths that did not require the damaged facilities to come back online first. For governments and enterprises across the UAE and wider Gulf who spent the last several years migrating critical infrastructure to AWS, the strikes are likely to accelerate a conversation that was already underway before October: how much of a country's digital backbone should sit inside one company's regional footprint, and how much should be spread across borders, providers, or state-backed alternatives.
Whatever the answer, the era of treating cloud outages as a purely technical inconvenience is over. The servers were, this time, quite literally under attack.
Published in The Outspoken Digest



