Data centre risk registers have always covered outages, cooling failures, intrusions and cable cuts. They have not generally covered ballistic missiles.
That is changing. During the current escalation involving Iran, at least five data centres in the Gulf have reportedly been hit, and the United States has reportedly struck an Iranian data facility. The distinction that matters is not the target list but the method: this is physical attack on computing infrastructure, not the cyber intrusion the industry has spent two decades preparing for.
The Bahrain strike
The most prominent case is an Amazon data centre in Bahrain, which was reportedly hit by a missile for the second time late last month.
Amazon has not commented publicly on the reported attack. Amazon Web Services has continued to show service disruptions affecting the region following an earlier incident on April 30, and satellite imagery has reportedly indicated extensive damage at the site.
After the July 21 strike, Iranian officials said via Telegram that the facility was targeted because AWS supplies cloud services underpinning US military intelligence work. Amazon participates in the US government’s Joint Warfighting Cloud Capability programme, a contract worth roughly $9 billion, alongside Google, Microsoft and Oracle.
That is the uncomfortable logic at the centre of this. A commercial cloud region and a defence contractor’s server estate can be the same building.
A published target list
Iran’s Islamic Revolutionary Guard Corps has not been ambiguous about treating technology infrastructure as a military objective. Early in the conflict it released a list of 29 technology-related sites across the region it described as potential targets, naming facilities linked to Amazon, Google, Microsoft, Nvidia and Palantir.
Iran’s broader approach here is familiar. For years it has offset conventional military disadvantage by going after economic infrastructure across the Gulf, refineries, export terminals and tourism assets among them, disrupting regional economies and the international businesses operating inside them. Data centres have been added to a list that already existed.
What is exposed
The timing is awkward, because the Gulf’s AI commitments are enormous and mostly still under construction.
Saudi Arabia has directed a significant share of sovereign wealth toward AI development. The UAE has partnered with the United States on Stargate, a $500 billion data centre programme billed as the largest AI infrastructure project outside the US, with OpenAI, Oracle, Nvidia and Cisco involved. Across Bahrain, Kuwait, Oman, Qatar, Saudi Arabia and the UAE, more than $2 trillion in AI-related commitments have been announced through partnerships with the United States, with a corresponding pullback from comparable Chinese technology.
Every one of those decisions tied regional infrastructure more closely to American strategic interests. That alignment is exactly what makes the facilities valuable, and it is also what makes them worth hitting.
The investor question
Helima Croft, head of global strategy at RBC Capital Markets, said the attacks could damage investor confidence in the region’s ambition to become a leading AI hub.
Her wider point is about what these incidents reveal. Technology companies now sit inside military operations and international diplomacy, not adjacent to them, and governments may be prepared to act directly to defend critical AI infrastructure in future conflicts.
For anyone underwriting a thirty-year asset, that reframes the calculation. A data centre is not a diversified portfolio. It is a fixed, expensive, mapped installation that cannot be moved, and insurance for war risk on that kind of asset is neither cheap nor straightforward.
The security assumption that just broke
The lesson landing hardest is a simple one. Protecting the compute layer is becoming a defence problem of the same class as protecting pipelines, ports and power stations.
Redundancy across availability zones handles hardware failure. It does not handle a facility that has been struck twice.
