This has been a week in which the physical and cyber dimensions of the US-Iran conflict converged on critical infrastructure in ways that should be on every healthcare security program's radar — not because healthcare is a direct target of the current campaign, but because the infrastructure healthcare depends on increasingly is.
On the cyber side, water utilities across at least seven states have reported hostile activity against operational technology systems since July 26. Federal investigators are examining potential Iran involvement, and the operational patterns are consistent with prior Iran-affiliated campaigns against US water infrastructure. No attribution has been formally confirmed. What has been confirmed is the scope, the targeting of Rockwell Automation and Allen-Bradley PLCs, and the coordinated multi-state timing.
On the physical side, CNN reported Monday that Iran has struck at least five data centers in the Gulf region since April, including a second missile attack on an Amazon Web Services facility in Bahrain in late July. The United States has responded by striking an Iranian data center. Data centers — which have been cyberattack targets for decades — are now being physically attacked in an active armed conflict for the first time.
These are two separate campaigns with separate tactics and separate geographic footprints. They share a strategic logic: Iran is inflicting economic pain on the United States and its Gulf allies by targeting the infrastructure that powers the AI economy, at a cost — primarily drones and missiles — that is low relative to the damage caused.
The Physical Data Center Threat: What's Actually Happening
Iran published a target list of 29 regional tech facilities it planned to strike, including sites owned by Amazon, Google, Microsoft, Nvidia, and Palantir. The IRGC's stated justification: Amazon holds numerous US government contracts, including participation in the $9 billion Joint Warfighting Cloud Capability project alongside Google, Microsoft, and Oracle. In the Iranian regime's framing, a data center serving US military cloud contracts and commercial AI workloads simultaneously is a legitimate military target.The AWS Bahrain facility has shown disruption on Amazon's service dashboard since the initial April 30 attack. Satellite imagery has confirmed extensive physical damage to the facility. AWS has not commented publicly. A second strike hit the same facility on July 21.
The broader Gulf context explains why these facilities are concentrated targets. Saudi Arabia, UAE, Bahrain, Kuwait, Oman, and Qatar have collectively pledged more than $2 trillion in AI-related investments with the United States — including the UAE's Stargate data center project, a $500 billion facility being built in partnership with OpenAI, Oracle, Nvidia, and Cisco. These investments came with a condition: divestment from Chinese equivalent technology. That alignment with the United States has made the region's AI infrastructure a target specifically because Iran can justify the strikes as hitting US military-adjacent assets.
Andrew Reddie, professor of public policy at UC Berkeley, framed the targeting logic precisely: "If you're Iran and you're looking at Amazon, it might as well have an American flag painted all over it." Data centers don't carry a sticker identifying their content as military or commercial — they carry both, simultaneously, which gives Iran its targeting justification.
What This Means for Data Center Resilience Planning
Data centers have always been designed with redundancy — to protect against natural disasters, cable cuts, and equipment failures. That redundancy architecture is now doing work it was never designed for: absorbing missile and drone strikes in an active conflict zone. The good news is that the redundancy generally works. When one data center goes down, workloads and data can usually be accessed from a different region. The AWS Bahrain disruption has been ongoing, but AWS's multi-region architecture has kept most affected workloads running.The harder problem is what comes next. Physical attacks on data centers are a new risk class that changes the calculus for facility location, insurance, and architecture decisions in ways the industry is still working through. Insurance costs are "ballooning — if you can get it at all," per Joe Macejak of Marsh. Some insurers are declining certain risks entirely. Tech companies building in the Gulf region are facing a coverage gap that can't be fully transferred even when coverage is available — at a moment when chip costs, construction costs, and labor are all rising simultaneously.
For organizations with cloud workloads in Gulf-region availability zones, the practical question is whether their cloud architecture treats Gulf regions as primary or as supplementary. The answer shapes the resilience posture.
The Cyber Campaign: What Is and Isn't Confirmed
The water utility attacks that began July 26 are connected to the same US-Iran conflict context, but the attribution picture is more complex than the data center story and requires careful handling.What is confirmed: hostile cyber activity against OT systems at water utilities in at least seven states, with the FBI confirming activity specifically against Rockwell Automation and Allen-Bradley PLCs. Multiple federal agencies are engaged. The scope, timing, and target type are consistent with prior Iran-affiliated campaigns, including CyberAv3ngers' 2023 campaign against water utility PLCs and the IOCONTROL malware kit developed between 2024 and 2025.
What is not confirmed: formal attribution to Iran or any specific threat actor. The FBI's public advisory did not name a culprit. CISA's Advisory AA26-097A, updated July 22, warned of Iranian-affiliated actors targeting PLCs broadly — but the advisory predates the July 26 attacks and doesn't attribute those specific incidents. A WaterISAC notice described the Minnesota activity as aligning with an earlier Iran-affiliated campaign, but WaterISAC subsequently clarified it had not assessed attribution publicly. President Trump offered an alternative attribution — Minnesota's governor — without evidence. The technical community's assessment, including Tenable's analysis, points toward CyberAv3ngers operational patterns, but that assessment is not the same as confirmed attribution.
Security programs should be making their defensive decisions based on the confirmed technical indicators — the PLC brands targeted, the attack methods documented, the cellular-connected OT exposure pattern — rather than waiting for attribution confirmation that may be slow to arrive or politically complicated.
The Strategic Pattern: Economic Pain at Low Cost
The strategic logic connecting the physical data center attacks and the cyber water utility campaign is the same: inflict economic and operational pain on the United States and its allies at a cost that is low relative to the damage caused. Drones and missiles against data center facilities. Exploitation of known, long-documented PLC vulnerabilities against water utilities that have been warned about those vulnerabilities for years.Neither campaign requires novel capability. The physical attacks require drones and missiles Iran already has. The cyber campaign requires exploiting vulnerabilities in internet-exposed PLCs that have been documented in federal advisories since at least 2023. The constraint isn't capability — it's which targets are hardened enough to make the cost-benefit calculation unfavorable. Gulf data centers are not hardened against physical attack. US water utilities are not hardened against PLC exploitation. Both are therefore viable targets.
This is the threat model that healthcare security programs should be internalizing: the campaigns that actually execute at scale against critical infrastructure are not the ones that require novel zero-days or sophisticated tradecraft. They are the ones that find the gap between what federal advisories have been recommending for years and what organizations have actually implemented.
What This Means for Healthcare
Healthcare organizations are not current targets of either campaign. But healthcare depends on the same cloud infrastructure, the same OT-adjacent systems, and the same internet-connected devices that are being targeted in both campaigns.Cloud workload geography deserves a fresh look
Healthcare organizations using AWS, Azure, or Google Cloud for clinical AI workloads, data storage, or administrative systems should understand where those workloads run geographically and what the failover architecture looks like. The AWS Bahrain disruption has been ongoing since April. Most healthcare organizations are unlikely to have Gulf-region primary workloads, but any organization using Gulf availability zones for latency, cost, or data residency reasons should verify that their architecture treats those regions as secondary with automatic failover — not as primary with manual recovery procedures.The broader question the physical data center attacks raise is whether cloud resilience planning for healthcare workloads now needs to account for geopolitical risk in region selection, not just natural disaster and infrastructure risk. That is a new consideration for most healthcare cloud architecture frameworks.
The water utility OT attack surface is the healthcare biomedical attack surface
The water utility campaign's confirmed attack surface — internet-exposed PLCs managed through consumer-grade remote access software by resource-constrained facilities — describes the healthcare biomedical device environment with different nouns. Infusion pumps, patient monitors, building automation systems, and laboratory instruments that are internet-accessible or remote-access-managed with inadequate controls share the same structural vulnerability. The same strategic logic that makes water utilities viable targets at low cost applies to healthcare OT environments.Healthcare security programs that reviewed the water utility attacks as a sector-specific story should revisit that framing. The campaigns targeting critical infrastructure are finding the gap between advisory and implementation — and that gap is present in healthcare OT environments.
The insurance signal is worth tracking
The data center insurance market tightening — costs rising, some insurers declining coverage, coverage gaps that can't be fully transferred — is a leading indicator for how cyber insurers will respond to AI infrastructure risk more broadly. Healthcare organizations that rely on cyber insurance as part of their AI infrastructure risk management strategy should be monitoring whether similar tightening appears in healthcare AI coverage terms. The Gulf data center situation is an accelerated version of a process that will eventually reach healthcare AI infrastructure risk pricing.The Bigger Picture
The confluence of physical and cyber attacks on critical infrastructure in the same week — against the same geopolitical backdrop, using the same cost-efficient-damage logic — is a signal that the threat model for critical infrastructure has changed in ways that security planning frameworks built in 2020 or 2022 don't fully account for. Data centers can now be bombed. Water utility PLCs can be disrupted across seven states simultaneously with pre-existing, documented vulnerabilities. Both campaigns are executing now.For healthcare security programs, the actionable position is the same one the water utility post outlined on Monday: the campaigns that succeed are the ones that find the gap between what federal advisories recommend and what organizations have actually implemented. The gap in healthcare OT environments is real and documented. The window to close it is defined by when a similar campaign finds it — not by when the advisory was issued.
Key Links
- CNN Business: AI data centers have become sitting ducks in the Iran war (August 3, 2026) (Paywall)
- The Conversation: Why Iran Targeted Amazon Data Centers and What That Does — and Doesn't — Change About Warfare
- New Arab: Gulf data centres targeted by Iran amid fears for AI economy
- Washington Times: New satellite imagery confirms Iranian attack on Amazon Web Services data centers in Bahrain
- The Register: Iran says it's struck offline AWS facility in Bahrain... again
- Compute Forecast: Gulf AI Infrastructure Physical Security Was Never Planned For
- The Register: Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
- SecurityWeek: US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
- CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit PLCs (Updated July 22, 2026)
- bregg.com: 30 Utilities in 48 Hours: What the Minnesota OT Attacks Mean for Healthcare Security Programs
- bregg.com: Seven States, One Campaign: The Water Utility OT Attacks Keep Spreading