Skip to main content

Bare Blogs

Why Iran Is Hitting Data Centers?

Attacks by Iran on data centers have made cloud infrastructure the victim of crossfire
Iran
Illustration: BareBlogs










Why Iran Is Hitting Data Centers: The Full Story













Why Iran Is Hitting Data Centers?

Short Answer

Iran’s Revolutionary Guard has struck commercial cloud data centers in the UAE and Bahrain because it says those facilities support US military and intelligence work. On March 1, 2026, drones hit three AWS sites in a single night, the first confirmed military attack on a major cloud provider in history. The strikes have since expanded to other tech companies and raised a legal question nobody has fully answered: when civilian and military data share the same servers, what actually counts as a legitimate target?

Quick Summary

  • On March 1, 2026, Iranian Shahed drones struck three AWS data centers, two in the UAE and one in Bahrain, in the first confirmed military attack on a major cloud provider.
  • Iran’s IRGC claimed responsibility, saying the facilities supported US military and intelligence operations.
  • The strikes knocked out two of three availability zones in the UAE region at once, disrupting banks, payment apps and ride-hailing services for days.
  • On March 31, Iran named 18 major US tech firms as legitimate targets. Further strikes hit Bahrain again on April 1 and reportedly an Oracle facility in Dubai on April 2.
  • Legal experts are split on whether the strikes were lawful, since the facilities hosted a mix of civilian and military workloads on the same infrastructure.

Timeline showing escalation of Iranian attacks on AWS and Oracle data centers from March to April 2026

Figure 1: How the data center strikes escalated

Why Iran Is Targeting Data Centers

For years, the assumption was that cloud infrastructure was too abstract to be a war target—all software, no real address. That assumption ended on March 1, 2026, when Iran struck physical AWS buildings with drones.

Iran’s Islamic Revolutionary Guard Corps (IRGC) claimed responsibility and said the targeted data centers were supporting enemy military and intelligence operations. IRGC’s stated justification specifically named AI systems, including Anthropic’s Claude, as being hosted on the affected AWS infrastructure and used for intelligence assessment and target identification ahead of strikes on Iran. It’s worth being precise here: this is Iran’s own claimed justification for the strikes. Neither AWS nor US officials have confirmed which specific systems or workloads were running at the struck facilities. One contractor CEO told DefenseScoop that classified government workloads are held in separate, US-only facilities, while acknowledging that contractor and non-operational data at the struck sites “may have been impacted.”

This wouldn’t be the first time commercial cloud infrastructure has been tied to military use in this conflict. In 2025, Microsoft revoked Azure cloud access for an Israeli military intelligence unit after reporting found the unit had been using Azure infrastructure in the Netherlands to store surveillance data and run AI language models. Iran’s targeting logic draws directly on precedents like that one.

The deeper issue is structural. Large commercial data centers host banking apps and enterprise software right alongside government services and, increasingly, defense-related workloads. That mixing happens for cost efficiency, not because anyone wants a bank and a battlefield AI model sharing a building. But it creates exactly the kind of ambiguity that Iran appears to be exploiting.

What Happened When the Drones Hit

The March 1 strikes hit hard. Two of the three availability zones in AWS’s ME-CENTRAL-1 (UAE) region went down simultaneously, along with a Bahrain facility damaged by a nearby explosion. Because standard cloud redundancy assumes zones fail independently, not two at once, Tom’s Hardware reported that only customers running fully multi-region setups came through unaffected.

Infographic showing banking and service disruptions after the March 2026 AWS data center drone strikes

Figure 2: The immediate fallout from the March 1 strikes

The customer impact was immediate and visible. Emirates NBD, First Abu Dhabi Bank and Abu Dhabi Commercial Bank all reported service disruptions. Ride-hailing app Careem, payment platforms Hubpay and Alaan, and data company Snowflake also went down for Middle East customers. AWS advised affected customers to activate their disaster recovery plans and shift workloads out of the region.

AWS’s own response tells you how serious the damage was. According to Data Center Dynamics, the company waived all usage-related charges for the ME-CENTRAL-1 region for the entire month of March 2026, applied automatically to every affected customer account.

The Attacks Kept Escalating

March 1 turned out to be the opening move, not the whole story. On March 31, Iranian state media announced it would target a list of 18 major US technology companies, including Microsoft, Google, Apple, Meta, Oracle, Intel, HP, IBM, Cisco, Dell, Palantir and Nvidia. AWS was notably absent from that list, likely because it had already been struck weeks earlier.

Grid graphic listing 18 US technology companies named as targets by Iran's IRGC in March 2026

Figure 3: The expanding list of named targets

The follow-through came fast. A second drone hit an AWS facility in Bahrain on April 1, this time explicitly following a round of US military strikes. The next day, Iranian state media claimed a strike on an Oracle data center in Dubai. By mid-June, the IRGC was still claiming new strikes on Amazon’s Bahrain infrastructure, though Bahraini officials disputed some of these claims, saying they intercepted the attack before it reached its target. AWS’s Bahrain region has remained marked as “Disrupted” on its status page since the original March strikes.

Under the Law of Armed Conflict, civilian infrastructure is supposed to be protected from attack, unless it’s genuinely supporting military or intelligence operations. That single exception is where the entire legal debate over these strikes lives.

Comparison graphic of legal arguments for and against the lawfulness of strikes on AWS data centers

Figure 4: Two competing legal readings of the same strikes

An analysis from Just Security concluded that if Amazon’s cloud services were genuinely enabling military AI capability at scale, that use could qualify the facilities as lawful targets. But Vincent Boulanin, director of the governance of AI program at the Stockholm International Peace Research Institute, takes the opposite view: AWS data centers most likely handle overwhelmingly civilian workloads, and striking them wasn’t lawful under that framework.

Just Security also raised a practical alternative: if the goal was denying military access to specific systems, more targeted cyber operations could have achieved that without physically destroying infrastructure that banks and ordinary businesses depend on. Whether that option was realistically available in the middle of an active war is a separate question, and one the legal analysis doesn’t fully resolve.

The core problem, though, isn’t really about intent. It’s about visibility. From outside a data center, there is often no reliable way to tell which server racks are running a bank’s transaction system and which are running something with military relevance. That ambiguity is precisely what makes this kind of target so contested, and so hard to defend against.

What This Means for the Cloud Industry

The consequences are already extending well past this one conflict:

  • Insurance is a real problem. Standard commercial policies typically exclude acts of war, which means companies hit by these strikes may have little to no legal or financial recourse.
  • War-risk coverage exists, but it’s expensive and hard to source, especially for infrastructure in a region now understood to be an active target zone.
  • Investment risk has gone up. Data center buildouts are long-term bets, and any region seen as a plausible military target now carries a higher risk premium for investors.
  • Physical vulnerabilities that were always theoretical—exposed cooling systems, power infrastructure, single points of failure—are now demonstrated realities rather than hypotheticals.

None of this is likely to reverse the buildout of AI infrastructure in the Gulf. But it will almost certainly change where new capacity gets built, how it’s insured, and how seriously physical security gets treated in a part of the tech stack that used to be thought of as purely digital.

Frequently Asked Questions

Iran’s drones caused real physical damage, structural damage, power disruption, and fire suppression water damage at two AWS facilities in the UAE, plus damage from a nearby explosion at a Bahrain site. AWS has said the recovery would be prolonged given the physical nature of the damage, though it has also said customer data was not deleted.

That’s Iran’s stated justification for the strikes, not an independently confirmed fact. Neither AWS nor US officials have confirmed which specific AI systems or workloads were running at the affected facilities.

Experts are genuinely split. One reading under the Law of Armed Conflict says facilities supporting military AI can be legitimate targets. Another argues that because these facilities mostly ran civilian and commercial workloads, striking them wasn’t lawful. There’s no settled answer.

On March 31, 2026, Iranian state media named 18 US technology firms as legitimate targets, including Microsoft, Google, Apple, Meta, Oracle, Intel, HP, IBM, Cisco, Dell, Palantir and Nvidia.

Standard commercial insurance typically excludes acts of war, so affected companies may have limited recourse. Dedicated war-risk coverage exists but tends to be expensive and difficult to obtain for infrastructure in an active conflict zone.

Explore More Geopolitical & Tech Analysis

For more research-driven analysis on artificial intelligence, digital infrastructure, global conflicts, and technology policy, explore the Tech & AI, World, and Research categories on BareBlogs.






Social Share
error: Content is protected !!