AWS says it cannot restore access to some cloud resources in Bahrain and the United Arab Emirates following physical damage during the Iran war (source). The affected infrastructure includes AWS’s Bahrain Region and one availability zone in the UAE. The company reported that the damage in Bahrain crossed multiple availability zones and exceeded what its regional and multi-AZ services were designed to withstand.
AWS Confirms Inaccessible Resources in Bahrain and the UAE
AWS disclosed the recovery status on September 15, 2026. According to reporting by Reuters, AWS cannot restore access to its cloud-computing infrastructure in Bahrain.
The company also cannot restore resources and data stored exclusively in mec1-az2, one of three availability zones in the UAE Region. AWS continues working to recover resources in the wider UAE Region and the other two affected zones. The disruptions began in March after US and Israeli attacks on Iran prompted retaliatory strikes against Israel and Gulf states hosting US military bases. AWS said two UAE facilities were directly struck. A drone strike near its Bahrain infrastructure also caused physical damage.
AWS has not said that every workload or backup in these locations was lost. The confirmed position is narrower: some resources and data remain inaccessible, and AWS has exhausted its options for restoring Bahrain resources that customers did not migrate before the Region became unavailable.
The Bahrain Damage Crossed Multiple Availability Zones
AWS Regions contain separate availability zones designed to isolate infrastructure failures. Businesses can distribute applications across these zones so that a problem in one location does not take down the entire service.
The Bahrain incident went beyond that design assumption. AWS said the physical damage spanned multiple availability zones and exceeded what its regional and multi-AZ services were built to withstand.
The first Bahrain availability zone was damaged in March. AWS then recommended that customers migrate workloads to other Regions. Most customers reportedly completed that migration before disruption to a second availability zone made the Bahrain Region unavailable in April.
AWS helped affected customers re-establish operations in other Regions. Recovery depended on whether customers had usable backups, replicated resources or alternative systems outside the affected infrastructure.
The UAE Recovery Remains Incomplete
AWS is replacing damaged infrastructure in the UAE and continues working on the two other affected availability zones. The company expects to provide further updates on UAE restoration over the coming months. Resources hosted exclusively in mec1-az2 remain inaccessible. AWS has not confirmed that the entire UAE Region is permanently unavailable.
The company expects to provide another update on Bahrain operations in early 2027.
HostScore’s Take
The AWS incident is an extreme event but its lesson applies to ordinary cloud deployments. Businesses should not treat “multi-AZ” as another way of saying “fully backed up”. Multi-AZ architecture protects against many hardware, network and facility failures. It becomes less effective when physical damage, regional dependencies or operational disruption affects several zones simultaneously.
Businesses running important workloads should verify five parts of their recovery design:
- Backup location: Copies stored inside the primary region may remain exposed to the same regional incident.
- Recovery testing: An enabled backup job does not prove that files, databases and application services can be restored together.
- Cross-region dependencies: DNS, credentials, encryption keys, container images and deployment files must remain available during recovery.
- Recovery objectives: The recovery point objective defines how much data the business can lose. The recovery time objective defines how long the service can remain unavailable.
- Provider concentration: An additional copy held with another provider can reduce dependency on one cloud platform, although it also increases cost and operational complexity.
Businesses subject to data residency rules may not be able to copy data to any available Region. Their recovery plans must identify approved jurisdictions before an incident occurs. AWS provides the infrastructure for backups, replication and cross-region recovery, but users still need to configure and test those systems. The Bahrain and UAE incident shows why cloud availability and data recoverability must be planned as separate requirements.