惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Privacy & Cybersecurity Law Blog
WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
腾讯CDC
人人都是产品经理
人人都是产品经理
小众软件
小众软件
V
Visual Studio Blog
S
Secure Thoughts
J
Java Code Geeks
V
V2EX
量子位
The Hacker News
The Hacker News
酷 壳 – CoolShell
酷 壳 – CoolShell
Security Latest
Security Latest
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Spread Privacy
Spread Privacy
博客园 - 叶小钗
T
Threat Research - Cisco Blogs
Security Archives - TechRepublic
Security Archives - TechRepublic
T
Tailwind CSS Blog
Cloudbric
Cloudbric
S
SegmentFault 最新的问题
AI
AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Application and Cybersecurity Blog
Application and Cybersecurity Blog
IT之家
IT之家
T
Tenable Blog
S
Security @ Cisco Blogs
月光博客
月光博客
雷峰网
雷峰网
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
C
Cybersecurity and Infrastructure Security Agency CISA
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
Attack and Defense Labs
Attack and Defense Labs
博客园 - 三生石上(FineUI控件)
Hacker News - Newest:
Hacker News - Newest: "LLM"
有赞技术团队
有赞技术团队
N
News and Events Feed by Topic
阮一峰的网络日志
阮一峰的网络日志
TaoSecurity Blog
TaoSecurity Blog
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
K
Kaspersky official blog

RUSI: Latest Commentary

Armenia’s Election: A Win for Pashinyan, Yet the Kremlin Long Game Persists The End of Orbánism? Bosnia, Magyar and Europe’s Strategic Credibility The Curious Case of the Delayed Investment Plan The Energy Supply Cliff is Alarmingly Near Europe Means Business on Cloud and AI Sovereignty No-Rules Based Order: The World As It Really Is The Nathan Gill Case: Isolated Foreign Malign Interference Case or a Broader Hybrid Threat? Armenia’s Election and the Future of Security in the South Caucasus Reforming Defence: Lessons from the UK Defence Restructuring History Re-Establishing Japan’s Intelligence Capability – ‘Spy Paradise’ lost? Illegal High Street Enterprise. Closed for Business, Open for Crime Hollowing Out Lebanon: How Pressure on Hezbollah Could Save It The Inextricable Link Between Geopolitics, Security and Humanitarian Impact As US Scales Back Forces Earmarked for NATO, Opportunity Opens for Europe Turkey’s Iraq Gambit Amid the Strait of Hormuz Crisis Order Missiles and Bombs to Increase European Combat Air Mass, Not Drones Canada Calling: Lessons for Europe on Confronting the Financing of Political Interference Water and Cognitive Warfare Missing Intelligence: The Trump Administration, Iran and the US Intelligence Community The Peace and Security System has Three Functions. African States Need a Fourth Multi-Billion Dollar Guarantee Marketplaces Exploit Stablecoins for Scams Stolen Species, Missed Opportunities: Wildlife Laundering in Latin America The West’s Ukraine Sanctions Strategy has Lost its Way The UK’s Chagos Islands ‘Deal’: Where are We Now? Europe’s AML Package: A Strong Framework at the Wrong Time? How North Korea is Modernising its Defence NATO’s Rutte is Doing a Tough Job. Europeans Should Help Corporations Must Re-learn How to be Geopolitical Actors Why the US’s Financial Efforts to Keep the Hormuz Strait Open Failed The Real Test for Iran Comes After the War Four Alternative End States in Iran – the Only Good One Becomes Unlikely Crypto Moratorium is the Right Starting Point for Political Finance Reform UN Norms: Tackling the Rise of Cyber Capabilities The Gulf Does Not Want This War to Continue Who Pays the Price for Managing China-Related Risks in UK Universities? The Great Power Delusion: Western Governments and China A Decade-Long Struggle to Thwart Iran’s Drones Carries Warnings for the UK Creativity and Innovation: The Play Advantage Over 11,000 munitions in 16 Days of the Iran War: ‘Command of the Reload’ Governs Endurance The Strait of Hormuz Problem: What ‘Securing’ the Waterway Actually Requires The Threat No One is Talking About in Iran Europe's Power is Defined by the Ability to Take Action in Ukraine
Iranian Data Strikes Shake Global Digital Infrastructure
2026-03-19 · via RUSI: Latest Commentary

By targeting data centres in the Gulf, Iran has created global uncertainty about the resilience, sovereignty and security of digital infrastructures.

Before sunrise on Sunday 1 March, Iranian Shahed drones directly struck two Amazon Web Services data centres in the United Arab Emirates. That same morning, debris from a nearby strike damaged a third AWS data centre in Bahrain. Impacts to the facilities created significant disruption to financial, enterprise and consumer digital services in the UAE and the wider region. In the wake of the strikes, calls to treat data centres as strategic assets and critical infrastructure have grown louder.

Data centres and the digital services operating on them are critical to the economy and society, but also to defence. As we have written previously, Ukraine’s Delta battlefield management system is hosted on the public cloud, the US’s Maven Smart System (created by Palantir) is hosted by AWS, and Israel has leveraged cloud-hosted AI capabilities in its war on Gaza. Where data centres are dual-use – hosting both civilian and military workloads – targeting them to disrupt military capabilities can make strategic sense.

Nevertheless, this is the first time that kinetic capabilities have been used against public cloud infrastructure. And where Iran has stepped, others will likely follow. It is therefore necessary to better understand why Iran may have targeted these facilities and what are the possible strategic impacts.

Explaining Iranian Targeting

It is highly likely that Iran deliberately targeted data centres in the UAE. Iran has struck a number of targets in the Gulf since hostilities began with a relatively high degree of precision, while the drones used in the strike are very capable of hitting a large target like a data centre. Indeed, following the attacks, Tasnim – an Iranian news agency – published a list of ‘legitimate targets’ as defined by the Iranian Revolutionary Guard (IRGC), these included the offices and infrastructures of American technology companies such as AWS, Google, Microsoft, IBM, Oracle and Nvidia. The IRGC also told state media that attacks were intended to identify what role these facilities have in supporting enemy military and intelligence capabilities. Whether or not the decision to strike was made by the remaining Iranian leadership or by a more junior commander operating in a decentralised manner is largely irrelevant to the strategic considerations of striking US companies’ data centres.

quote

Where infrastructure is dual-use, it can legally be targeted providing it meets certain criteria. In this scenario, distinction is difficult because militaries cannot reliably or effectively determine whether hyperscale infrastructure is being used by the enemy and to what extent

Your authors identify three plausible rationales for deliberately targeting these locations.

First, striking data centres imposes costs. Gulf countries have invested heavily to encourage American technology companies to expand locally, aiming to diversify away from petrochemicals. Cheap land and energy have attracted computing and AI companies: AWS, Google, Microsoft, Nvidia, Oracle and others all own, operate, rent or partner with local companies to run facilities in the Gulf. Drone strikes damage Gulf states’ carefully-cultivated reputation as a neutral, peaceful place for investment, thereby disincentivising these and other companies from operating in the region, undercutting billions of dollars in investment.

Arguably, the same effect could be generated through targeting any commercial data centre where a foreign company is involved. For example, Alibaba and other Chinese companies have a smaller, but growing, presence in the region. However, targeting a US tech company comes with the added benefit that these companies drive overall growth in the US stock market, imposing further costs on President Trump’s economic agenda.

Such strikes on data centres therefore align with Iran’s objective of re-establishing deterrence through asymmetric methods: imposing reputational and physical pain on Gulf allies of the US, depleting precious air defence stockpiles, and imposing economic costs on its enemies (which is mainly through closing the Strait of Hormuz).

Second, targeting data centres can impact and provide information on critical capabilities. Cloud companies provide services to governments, including the military as well as critical national infrastructures. Both AWS and Google have had long-term contracts with the Israeli Defence Force and the US Department of War’s $9 billion Joint Warfighting Cloud Capability contract includes each of company as well as Microsoft and Oracle.

Enjoy our analysis and research? Ensure it shows up first on Google

Help your search results show more from RUSI. Adding RUSI as a preferred source on Google means our analysis appears more prominently.

It is highly unlikely Iran knew if either Israel or the US used the targeted data centres for military workloads. Therefore, Iran would have had low confidence in the strikes ability to degrade military capabilities, with the attacks mostly serving as a message to all supporters of US military capabilities. Were the strikes to have created observable impacts on Israeli and US military assets this would have been welcome, but there was not likely an assumption that it was guaranteed.

Finally, the attacks caused disruption. As remarked above, digital services including payment, banking and consumer products were disrupted. Normal people and businesses could not operate as they usually would. This has a psychological impact that brings home the reality of the conflict. Through the strikes, Iran further demonstrated the tangible threat it posed.

These explanations are not mutually exclusive, nor are they necessarily exhaustive. Iran may have intended to layer effects through the strikes to achieve multiple outcomes or simply to signal its own capabilities. Getting to grips with these and other motivations will be crucial to developing effective countermeasures and deterrence against future strikes.

How Could this Change the Strategic Environment

Based on the information presently available, some have argued that these strikes are unlawful under international law. A military owned/operated data centre is a lawful target, but one that is owned/operated by a hyperscaler for civilian workloads is civilian infrastructure and therefore protected under the principle of distinction. Yet militaries’ use of public cloud infrastructure muddies the water. Where infrastructure is dual-use, it can legally be targeted providing it meets certain criteria. In this scenario, distinction is difficult because militaries cannot reliably or effectively determine whether hyperscale infrastructure is being used by the enemy and to what extent. Hyperscale providers do not provide lists of their clients nor where they choose to host data and workloads. Moreover, their service is sold on its availability, meaning that workloads can (more or less) seamlessly migrate across regions and physical infrastructure.

Subscribe to the Military Sciences Newsletter

Stay up to date with the latest publications and events from the Military Sciences Research Group

To meet legal requirements, the military benefit of striking a dual-use data centre would have also to exceed the civilian harm – thereby meeting proportionality. Even assuming civilians are not caught in the strike, civilian harm may still arise due to the potential outages, loss of data, and impact on other critical infrastructure. Were these data centres hosting US or Israeli military workloads, targeting would not necessarily merit the harm to civilians and civilian infrastructures. While not justifying Iran’s actions, it does bear mentioning that the US and Israeli attacks have targeted Iranian civilian infrastructure, including physical and cyber attacks on their digital infrastructure.

Another reflection on Iran’s strikes is its challenge to arguments for cloud sovereignty based on localisation. In reaction to service interruption, AWS recommended its customers relocate workloads to other data centre regions located outside the conflict area. In this way, hyperscale cloud argues it can provide resilience that is not achievable through relying on data centres within a single national territory. Ukraine’s experience of expanding digital public services throughout Russian kinetic attacks further demonstrates this point, as does Estonia’s data embassy.

Nevertheless, the specific targeting of US technology companies introduces a problem. If these companies’ data centres are targets, does that change the risk calculus of using them to promote national resilience? Furthermore, if the integrity of national critical services is dependent on their ability to migrate globally, are our legal regimes sufficiently flexible to accommodate this? Or are governments prepared for other countries’ to be relying on data centres in their territory that are owned and operated by foreign companies? These and other questions are being addressed in RUSI’s ongoing work on cloud sovereignty.

Subscribe to the RUSI Newsletter

Get a weekly round-up of the latest commentary and research straight into your inbox.

Governments must also contend with the uncomfortable reality that their national resilience mapping has not kept pace with the speed of cloud adoption. Most states lack the granular understanding of which critical services depend on which hyperscale infrastructure, and where that infrastructure physically resides. This is not simply a technical failure; it is a governance one. Compounded dependence and delegated control and visibility pose distinct challenges to managing potential risks with existing policy tools, which are more focused on end products and services than on their shared architecture and underlying infrastructure. Developing that visibility must now be treated as a strategic priority, alongside harder questions about whether and how governments should mandate physical protection for data centres on their territory that are owned and operated by foreign companies – and what obligations, if any, those companies bear in return.

The strikes should nonetheless prompt careful rather than hasty conclusions. The strategic drivers behind the Gulf's rapid data centre expansion – cheap energy, sovereign wealth investment and the region's position between East and West – have not evaporated. Regulations in the European Union, UK and the US already treat data centres as critical or essential infrastructure, and pressure on other governments to follow suit will only intensify. What is clear is that the events of 1 March have added significant momentum to a debate that was already gaining force: whether cloud infrastructure can continue to be treated as a commercial utility, or whether it must be governed as a contested and consequential strategic asset, at the intersection of economic power and conflict.


WRITTEN BY

Joseph Jarnecki

Research Fellow

Cyber and Tech

View profile

Noah Sylvia

Research Fellow, C4ISR and Emerging Tech

Military Sciences

View profile