UAE — In early March 2026, drone strikes on two Amazon Web Services (AWS) data centers in the United Arab Emirates forced three facilities offline, necessitating the transfer of computing workloads to other regions. The incident marked the first time physical military attacks directly targeted and disrupted the data center operations of a major U.S. technology company.

The outages triggered disruptions across regional banking, payments, delivery applications, and enterprise software. AWS stated that it expected the recovery to be "prolonged, given the nature of the physical damage involved."

The event occurred as Gulf states reevaluate the security of their critical digital systems due to an increase in cyber threats and physical attacks on cloud infrastructure. Daily cyberattack attempts in the UAE surged from approximately 200,000 to as many as 700,000 as geopolitical tensions flared in recent months. The UAE's financial sector experienced a wave of sophisticated cyberattacks last week.

The UAE's Cyber Security Council noted that cybercriminals are increasingly using artificial intelligence (AI) to develop more advanced techniques. A report published by Help AG indicated that AI has become a force multiplier, enabling attackers to accelerate reconnaissance and adapt techniques in real time. In the first quarter of 2026, Help AG observed that the use of AI allowed attackers to complete operations 65% faster than before, with some AI-accelerated attacks causing damage less than 40 hours after initial access. "The signal across global research is consistent: attackers are compressing the attack lifecycle," the report authors noted. "The Middle East reflects the same pattern—but under higher exposure intensity," they added.

Abdulla Ebrahim Al Ahmed, chief government relations officer at e& UAE, said, "Organizations today need security that is continuously adaptive, locally aligned and designed to protect critical infrastructure and citizen data in an AI-driven environment." Aleksandar Valjarevic, acting CEO of Help AG, said, "Across the GCC, AI and sovereignty are already reshaping how digital infrastructure is designed, secured, and governed." Valjarevic added, "The findings of this year's report show that cybersecurity must now operate continuously, at machine speed, and in direct alignment with national resilience priorities." He also stated, "For organizations, the focus is shifting from adding more tools to building adaptive, measurable and locally aligned security capabilities that can withstand sustained pressure."

Sam Winter-Levy, a technology and international affairs fellow at the Carnegie Endowment for International Peace, said physical attacks on data centers "are only going to become more common moving forward as AI becomes more and more significant." Other companies, including Microsoft, Google, and Oracle, operate extensive cloud infrastructure across the Gulf.

Why It Matters

The drone strikes represent a new type of threat to digital infrastructure, directly impacting operations of a major U.S. tech company for the first time. The incident exposes vulnerabilities of critical digital systems in the Gulf region as cyber threats and physical attacks escalate. The increasing sophistication of cyberattacks, driven by AI, is causing Gulf states to focus on adapting their cybersecurity strategies to protect essential services like banking and payments.

This event contributes to a broader pattern of rising security concerns, leading to increased spending on information security. Gartner projects information security spending across the Middle East and North Africa (MENA) region to reach $4.07 billion in 2026, a 10.1% increase from 2025. Similarly, P&S Intelligence forecasts cybersecurity spending across the GCC to surpass $9.6 billion by 2032, up from $5.9 billion in 2025.