Data Centres

Iran’s widening cyber war puts data centres on notice

24 August 2026
7 minutes
From Gulf cloud campuses to a UK power plant, state-linked cyberattacks are spreading fast, and data centre leaders are being forced to rethink resilience.
Iran flag .png
Iran flag .png

Since the US and Israel launched coordinated strikes on Iranian nuclear infrastructure and IRGC targets at the end of February, the conflict has spilled well beyond missile silos and enrichment halls. It has reached into the racks and cooling plants of the commercial cloud, and it has triggered a wave of retaliatory cyber activity that security researchers say is still building.

The turning point for data centre operators came on 1 March, when Iranian drones struck two Amazon Web Services facilities in the United Arab Emirates, with debris from a nearby hit damaging a third AWS site in Bahrain. It was, by most independent accounts, the first time a hyperscale cloud provider had been deliberately targeted during a live conflict. Further strikes followed on an Oracle facility in Dubai and, weeks later, on Amazon’s Bahrain region again, which Iran’s Revolutionary Guard claimed to have “destroyed” outright.

The disruption rippled well beyond the region. Banking apps, payment platforms and ride-hailing services across the Gulf went dark for days. AWS itself described “structural damage, disrupted power delivery” and water damage from fire suppression systems, and urged customers to shift workloads out of the affected regions entirely. For an industry built on the promise of resilience through redundancy, having two availability zones fail simultaneously was a scenario few risk models had properly stress-tested.

Nuclear strikes, cyber fallout

The physical attacks on data centres cannot be separated from what happened to Iran’s nuclear sites, nor from the digital retaliation that followed. Threat intelligence teams have tracked a sharp rise in Iranian-linked denial of service campaigns, data-wiping malware and hack-and-leak operations since the strikes began, much of it aimed at Gulf energy and critical infrastructure targets, alongside renewed reconnaissance against industrial control systems.

For the data centre sector, the lesson is not that Iran alone poses a threat, but that the boundary between kinetic and cyber conflict has effectively dissolved. A facility hosting sensitive government or defence workloads can now find itself named on a target list published by a state actor’s media arm, exactly as happened when Tasnim, an outlet aligned with the IRGC, listed 29 sites belonging to Amazon, Microsoft, Google, Oracle, Nvidia and others as “legitimate targets” in the widening war.

Patrick Murphy, executive director of the geopolitical unit at advisory firm Hilco Global, has argued that the strikes mark a shift in how governments will need to classify digital infrastructure. He told CNBC that operators should expect data centres to be folded into “national security planning frameworks alongside energy facilities, telecommunications networks, water treatment plants and transportation hubs.”

Matt Peal, a director at the Centre for Strategic and International Studies, put it more bluntly to the Financial Times: “the Iranians view data centres as part of the conflict.” Once an adversary treats compute infrastructure as a legitimate military target, every hyperscale campus in a contested region becomes a point of geopolitical exposure, not just a point of technical failure.

The threat reaches British shores

The conflict’s cyber fallout is no longer confined to the Gulf. It was revealed this week that a small UK power plant was shut down for four days in July after a cyberattack attributed to hackers linked to the Iranian regime, in what is believed to be the first successful state-linked cyber intrusion to take a British energy facility offline.

The Department for Energy Security and Net Zero confirmed the incident involved a small-scale generator and insisted there was no risk to the wider grid, though the government has since briefed energy sector chief executives and issued fresh security guidance. It was reported the affected site was a small gas-fired “peaker” plant with a capacity of around 15 megawatts.

The timing is telling. The incident coincided with a wave of attacks on more than 30 US community water systems, and came months after NCSC chief executive Richard Horne disclosed that hostile states accounted for roughly three-quarters of the 200-plus incidents affecting UK critical national infrastructure in the year to May. For data centre operators, who sit downstream of the same energy grids and increasingly share supply chains and contractors with power generation, the message is that geographic distance from the Gulf offers no meaningful insulation.

A resilience problem, not just a security one

What makes this moment different from earlier eras of Iranian cyber activity, including the Stuxnet campaign against Natanz more than a decade ago, is the scale of collateral exposure. Stuxnet was a scalpel aimed at centrifuges. What is unfolding now touches banks, payment processors, universities and logistics platforms with no direct connection to the conflict, simply because they share a region, or a cloud region, with facilities deemed strategically significant.

This is not an isolated spike. Threat intelligence firm CyberProof recorded a 168 per cent year-on-year jump in global DDoS activity during the first quarter of 2026 alone, with more than 70 hacktivist groups launching campaigns tied directly to the Iran conflict. Industry association AFCOM’s latest survey found that more than half of data centre professionals now rate human-driven threats as the single biggest risk to their facilities, while analysts at DC Byte warn that operators must weigh a far broader spectrum of threats than the purely digital ones facilities were built to withstand. Kristina Lesnjak,

Legal voices are drawing the same conclusion from a different angle. Hannah Levin, a partner at Morgan Lewis who advises on data security incident response, has warned that a sophisticated attack on a data centre could prove “catastrophic” given the volume of data such facilities hold, with an outage likely to be far more widespread than the supply-chain incidents the industry has weathered before.

Dave Wulf, co-founder of the Center for Cross-Sector Coordination, notes the threat runs both ways: an attack on a water system or substation could just as easily take down the AI capability that other critical infrastructure now relies on in turn.

Some analysts expect future hyperscale investment to tilt towards regions seen as more politically predictable, including Central and Eastern Europe. Others counter that treating data centres as untouchable civilian infrastructure was always a fiction, and that operators everywhere, not only in conflict zones, now need to model deliberate, state-linked disruption alongside the usual roster of ransomware and insider threat.

For CISOs, the practical takeaway is that geopolitical monitoring can no longer sit apart from cyber defence planning. Segmenting critical workloads, hardening OT environments against remote access, and building genuinely independent failover across geopolitically distinct regions are no longer best-practice footnotes; they are becoming baseline expectations from insurers, regulators and boards alike.

Capacity has been tracking the fallout since the first strikes hit AWS facilities in March, including reporting on whether hyperscale data centres are becoming targets in modern warfare, coverage of the IRGC’s claimed destruction of Amazon’s Bahrain data centre, and analysis of the wider supply chain and energy risks facing Gulf data centre operators as the conflict continues to reshape how the industry thinks about risk.

What began as an attack on Iran’s nuclear programme has, in the space of a few months, forced a much wider reckoning across the data centre industry, one that now extends from Bahrain to a small generating station in Britain. Whether the next escalation comes from Tehran, from another state actor watching how effective these tactics have been, or from criminal groups opportunistically exploiting the chaos, the pattern is now established: critical digital infrastructure sits on the front line, and the industry’s defences, physical and cyber alike, are being tested accordingly and more widely than ever before.

Related stories

Data centres in the line of fire? What the US–Iran war means for the Cloud

Iran bans officials from using connected devices amid cybersecurity fears

Iran-US war: Data centre supply chain concerns amid energy anxieties

Capacity Middle East 2027

15 March 2027

Capacity Middle East is the region’s leading digital infrastructure event, uniting over 3,500 executives from more than 90 countries for visionary content and unrivalled networking and business opportunities.