Amazon just told customers in Bahrain and the UAE that their data is gone for good.
Six months after Iranian drone strikes hit AWS facilities, the company said on September 15 that it can no longer recover customer data and resources in the Middle East (Bahrain) region, me-south-1. One availability zone in the UAE region, me-central-1, is a write-off too. If your cybersecurity program treated a second zone as a survival plan, this is the week that plan failed.
You can patch a CVE.
You cannot un-explode a rack.
Two regions are now a write-off
Help Net Security’s reporting is blunt. AWS posted two updates and admitted permanent loss of objects, volumes, and managed resources that lived in those facilities. The restore window is closed.

A lot of architecture diagrams still draw an availability zone as if it were a different planet. It is a different building, often in the same metro, sharing power politics, flight paths, and regional conflict. Bahrain and the UAE were production, not a tabletop slide.
Cross-AZ replication is a campus boundary with better networking. If you ran primary in me-south-1 and called a replica in the same region offsite, you now own a paper failover. Country distance and provider distance are the copies that still exist.
Incident response for a dead region looks nothing like a ransomware war room. There is no decryptor to negotiate. There is no snapshot to mount if the snapshot lived next door. You inventory what still exists in other geographies, you declare what is gone, and you tell the business which processes cannot restart.
That conversation is overdue for every tenant that still treats the cloud as a single weather system.
Cybersecurity still treats infrastructure as immortal
The same week, NLnet Labs shipped Unbound 1.26.1 because every prior release of the recursive resolver had a critical heap overflow in its DNSSEC validator, CVE-2026-81642. An attacker who controls a malicious zone and can get your resolver to query it can reach remote code execution. DNS is the lookup path your firewall rarely inspects as a payload. Teams file that under cyber security hygiene and leave the box unpatched because it only answers queries.

Name resolution is how threat detection even finds the rest of your estate, how clients reach backups, and how you log into the jump host after the region goes dark. A resolver that dies or gets owned is another building you assumed would always be there.
Talos’s read on Japan in the first half of 2026 should finish the argument. Ransomware incidents there rose 4.7 percent year over year. The Gentlemen led, with leak-site listings more than doubling from January to July. Qilin ranked second and showed signs of AI use. Companies with capital under JPY 1 billion were 80 percent of victims.

Those SMEs lost because the restore path was a single NAS, a single vendor tenant, or a single on-site admin who also ran threat-protection tooling. Defense in depth on paper still collapses when backups share fate with production.
Physical destruction and ransomware encryption produce the same operational outcome. The bits you need stay gone with the host that held them.
Design recovery as if the building is gone
Stop arguing about whether a drone strike is in scope.
Scope is whatever deletes the only copy. Do this week, without a new platform purchase.
- Map every production dataset to the region, availability zone, and account that holds the only copy. If restore depends on the same region, you do not have a restore. Replicate out of the political and geographic blast radius, then prove a restore in the destination. A replication lag graph is not proof.
- Inventory recursive DNS. Patch Unbound to 1.26.1 or newer, or take the resolver off any path a stranger can influence. A malicious zone should not be an RCE primitive sitting under your name servers.
- If you just failed over, expect brute-force and scanning against whatever SSH, RDP, VPN, and admin portals came up in the surviving region. Tighten firewall allowlists to known egress, and put host-level blocking such as ipban or IPBan Pro on those boxes so leftover internet exposure does not become the second outage.
- Rehearse incident response for the region is gone. That drill names who declares data loss, who restores from the other country, and who tells customers. Security hardening tickets that only cover CVE scores will not run that meeting.
- Treat SME-scale estates the way Talos’s Japan numbers imply. One identity, one backup target, and one DNS resolver is a single fault. Split them on purpose and keep the split tested.
Your next outage may look like encryption, a resolver crash, or a building that does not reopen. The control that matters is a copy that already lived somewhere else, with a restore you have actually watched succeed.
Sources
- Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
- Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
