Amazon confirmed permanent data loss, and the cause deserves a slow read: drones and missiles struck AWS data centers in Bahrain and the United Arab Emirates, and the problems, in the company’s own words, exceeded what regional and multi-AZ services were designed to support. Some resources stored exclusively in the mec1-az2 zone can no longer be restored.
It was not a software failure. It was not a stolen credential. It was war, and the disaster category every resilience design treated as theoretical just got a data death certificate.
Multi-AZ was designed for a different world
The architecture lesson is harsh: multi-AZ protects against logical failures, the disk that dies, the rack that burns, the link that drops. Military attack does not fit that design: it strikes two zones on the same night, and the replica inherits the same battlefield.
Data that only existed in one zone stayed exactly where the conflict was. The redundancy worked as designed; the problem is the design never contemplated the right enemy.
The chronology and the bill
The attacks ran from March to July: the first wave on March 1st in the Emirates, the last on July 24 in Bahrain. AWS suspended billing for the region’s customers and issued about 150 million dollars in credits.
The asymmetry of the outcome is the whole lesson: restoration was possible for those with a copy outside the conflict theater. For zone-exclusive cases, it was not. Same infrastructure, same contract, opposite outcomes defined by a single architecture decision: where the copy lives.
Resilience went geopolitical
From here on, the rulebook changes for everyone designing infrastructure:
- Backup with an immutable copy outside the region, in a jurisdiction different from the primary. Immutable because the same event can compromise credentials; outside the region because the neighboring zone inherits the same risk.
- Multi-region that crosses jurisdictions, not just zones. The design that survives war has a copy thousands of kilometers from the theater.
- A risk map with physical and state-level variables: drone routes, regional tension, and sanctions join CVEs and disk failures on the board.
The parallel with the hypervisor ransomware lesson is direct: in both cases, backup reachable by the event (through the network or through geography) is not backup, it is the same victim at a second address.
Brazil’s chapter in the new rulebook
This is where Brazil enters the conversation: 205 data centers, an 88% renewable matrix, and distance from conflict theaters, assets the market still misprices. The R$ 2 trillion investment wave with ReData unlocked accelerates exactly the layer the new rulebook values: local capacity, clean energy, and stable jurisdiction.
For Brazilian-user workloads, the combination solves three chapters at once: latency the border cannot deliver, LGPD compliance, and distance from the conflicts now part of any serious architecture’s risk map.
Conclusion
The cloud has an address. For fifteen years the industry optimized latency and price; the next chapter adds the variable nobody wanted: physical security against state actors.
Whoever designs the 2027 architecture must answer a new question: how many thousands of kilometers do your data live from a conflict? If the answer is "I don’t know", that is this week’s inventory. The AWS case cost permanent data to those who never asked it.