AWS can't restore Bahrain and a UAE zone, six months after the drones
Two stories today about infrastructure that everyone assumed was recoverable: a cloud region that isn't coming back, and a bug bounty pipeline a criminal turned into a payday.
Amazon Web Services told customers it cannot restore its Bahrain region or one of its three availability zones in the United Arab Emirates, more than six months after drone strikes damaged the sites — its first public update since April. The line that matters is AWS's own: the damage "spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand." Multi-AZ redundancy is the thing cloud customers pay for, and AWS is conceding the design assumption failed — not just one building.
The history is short and ugly. In early March, two AWS data centers in the UAE were struck directly and a Bahrain facility was damaged by a nearby strike. Iran's Islamic Revolutionary Guard Corps claimed responsibility and tied the Bahrain target to Amazon's support of the U.S. military. By the end of April about 60 services in the region were still down, and the outages reached banking operations. AWS now says it has helped most Bahrain customers rebuild elsewhere and has exhausted every option for data that was not migrated before the region went fully unavailable. Restoration updates are promised for the UAE "in the coming months" and for Bahrain in early 2027. The company has not said whether any customer data is permanently lost, whether the damaged buildings can be repaired or must be replaced, or what happens to customers whose only backups lived in those zones.
Why it matters: the Gulf's AI build-out — including Stargate UAE's planned 5-gigawatt campus — was priced on cheap power and sovereign money, not on missile risk. That assumption is already being repriced: the UAE is weighing dispersing facilities, building some underground, and adding blast-resistant construction and interceptors. We covered that redesign when it surfaced — Iran war forces UAE to redraw its 5GW AI data center map. The new fact is harder to manage. A hyperscaler has now publicly written off a region's data, which is a question for insurers and regulators as much as for cloud architects, and a direct input into how much Gulf compute capacity anyone should underwrite.
CrowdStrike researchers concluded with high confidence that a hacker used a large language model to write the PhantomRaven malware — then cashed the access it produced through legitimate bug bounty programs. Per Axios, the attacker published malicious npm packages that delivered the credential-stealing payload; the harvested tokens and secrets opened up company assets, where he searched for vulnerabilities and submitted them for rewards, claiming payouts from at least nine companies in technology, retail and hospitality. The evidence for AI authorship is the tell-tale kind: leftover comments, placeholder fragments and token-analysis patterns consistent with generated code. Adam Meyers, CrowdStrike's senior vice president of counter-adversary operations, says the bounty route bought credibility as much as cash.
Two caveats worth keeping. Researchers could not determine whether the malware was used against those nine companies specifically, and found no sign the stolen data was sold on criminal marketplaces. And PhantomRaven itself is not new — its npm waves have been tracked since 2025, using remote dynamic dependencies and "slopsquatting" names that LLMs hallucinate into existence. The news is not that criminals use AI. It is that a public trust channel for reporting flaws has become a monetization path, and bounty triage teams are the ones who now have to tell a researcher from a racketeer.
What to watch: whether AWS gives Bahrain customers a firm restoration date or quietly retires the region, and whether bounty platforms start asking for provenance on AI-assisted submissions.
If a cloud region can be destroyed beyond recovery, does "multi-AZ redundancy" still mean anything — and who should carry that risk, the provider or the customer? Tell us in the comments.
Sources: CNBC · Reuters · The Next Web · Axios · Mezha · Sonatype