Skip to content

Build1 publisher3 min readPublished

AWS says the damage in Bahrain outran what multi-AZ was designed to absorb

A health dashboard update from AWS reports customer data lost for good in the Middle East. The account carrying its wording to me is a Thai-language post that a model drafted and a human editor checked.

The Engineer · Build desk

Illustration accompanying AWS says the damage in Bahrain outran what multi-AZ was designed to absorb

What happened

  • AWS published an update to its health dashboard on 15 September 2026, the first public update on the Middle East regions since April.
  • The update puts customer data in Bahrain's me-south-1 beyond recovery across all three availability zones, and in the UAE, me-central-1, in mec1-az2 while the other two zones are still being recovered.
  • AWS said it had assessed every affected piece of infrastructure and used every available option to recover data and resources that had not been migrated before the Bahrain region became unusable.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision A multi-AZ row in a design document no longer answers a durability question for a region. The artifact a reviewer should now ask for is a restore that lands in a different region and a list of data that exists in exactly one place.
  • exposure The loss falls on the customers who kept a single copy inside the affected zones with no cross-region replica, a group the post places among the minority that ignored the April advice to migrate.
  • cost Recovery for everyone else was a rebuild somewhere else, paid for in engineering time against whatever backups existed. AWS assisted; it did not restore.
  • precedent Physical threat modelling is entering site specification: the UAE is weighing dispersed locations, underground construction, blast-resistant concrete and drone and missile interception for its AI data centre plans, and the post reports AWS is looking at the same.

A multi-AZ deployment buys independence between zones. The post sets out the standard three-zone diagram and the assumption sitting under it, that failures arrive one zone at a time [15]. Three attacks spread over months, each producing structural damage, interrupted power into the infrastructure, and in some cases firefighting that added water damage, do not arrive that way [6][8]. A Korean report cited in the post attributes the physical damage to water flowing in during the firefighting [9].

Across the two regions named, four of six zones are now described as unrecoverable: all three in Bahrain, plus mec1-az2 in the UAE, where mec1-az1 and mec1-az3 are still listed as recoverable [24][3][4].

The post renders the dashboard update in Thai; translated back, AWS said the damage spanned multiple availability zones and went past what its regional and multi-AZ services were designed to absorb [2].

The post also cites reports calling this a first. One says it is the first time data from a global cloud company was destroyed and lost through a military operation [10]. Another says the attacks are believed to be the first case of war disrupting a major American hyperscaler [11]. One of the cited reports says the AWS outage affected some banking operations at the time [12].

The post dates the episode from 1 March to 15 September and calls that six months [22]. It is 198 days [23]. AWS told customers to move workloads out from April, and says most did so before the Bahrain region became unusable [7]. The customers whose data is gone are, in the post's reading, the ones that had not moved and held no backup or replica in another region [14].

All of the above comes from a single dev.to post dated 18 September 2026, credited to Nokka, which says it was drafted by the deepseek-v4.1-flash model through Nous Research's Hermes Agent and then checked and edited by Nokka [21]. It quotes AWS in Thai translation and does not reproduce the English original [21].

Two of the three things the post says to add are cheap. Know which data exists in exactly one place, and test a real restoration instead of testing that the backup ran [17]. The second is where teams lose, because the post's account of the failure is not that backups vanished but that there was no original infrastructure left to restore into [18].

Whether the concession changes your review depends on one condition holding for your region as it held for Bahrain's: the post says all three Bahrain zones sat in the same area and were hit at the same time [16]. Where zones are correlated like that, the region is the durability unit, and the recovery AWS describes is customers rebuilding operations in another region from existing backups [13].

What to watch

  • AWS has promised an update on the UAE in the coming months and on Bahrain in early 2027; whether either names a rebuild date is the thing to read for.
  • Whether the English text of the 15 September dashboard update matches the Thai translation this post carries.
  • Whether other publishers with direct access to the dashboard confirm that all three Bahrain zones are unrecoverable.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories