Iran-linked threats and attacks expanded from shipping lanes to digital infrastructure across the Gulf, with reports naming Google, Amazon, Oracle, IBM, and Nvidia facilities in the Middle East as potential targets and describing earlier drone strikes that disrupted AWS operations in the UAE and Bahrain. Regional authorities later denied an IRGC claim that Oracle’s Dubai data center had been hit, but multiple reports said missile and drone attacks had already affected energy, desalination, and industrial sites in Kuwait and the UAE while raising fears for data centers and telecom assets tied to U.S. firms. The conflict’s cyber dimension also spilled into enterprise systems, with analysts warning that retaliation was increasingly aimed at civilian-adjacent technology, logistics, finance, and cloud dependencies rather than a single decisive cyberattack.
At the same time, the Strait of Hormuz became a pressure point for both maritime traffic and internet connectivity. Large-scale GPS/GNSS spoofing, AIS suppression, dark vessel activity, and selective transit controls disrupted hundreds of ships, while repair and construction work on subsea cables slowed or stopped as security conditions deteriorated. Meta’s 2Africa/Africa2 cable project was delayed after Alcatel Submarine Networks declared force majeure, and Iran-linked media proposed licensing, taxing, and controlling undersea cable operations in the strait, with some outlets openly discussing cable disruption as leverage. Analysts warned that at least six major fiber systems crossing Hormuz underpin Gulf cloud services, finance, and trade, meaning prolonged interference or damage could delay repairs, force traffic onto riskier overland alternatives, and threaten the region’s broader digital-economy ambitions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Tom's Hardware reported that IRGC-affiliated outlets Tasnim and Fars discussed licensing foreign cable operators, imposing annual fees, and placing cable maintenance under Iranian control in the Strait of Hormuz. Fars also raised the prospect of disrupting the cables to impose economic costs.
Windward said maritime security conditions around Hormuz, Fujairah, and the Gulf of Oman deteriorated sharply after the launch of Project Freedom. The escalation combined kinetic attacks, GPS jamming, AIS shutdowns, and coercive Iranian maritime activity into a single high-risk environment.
Windward reported that SAR imagery collected on May 5 identified 167 commercial-size vessels near Hormuz, including 146 operating dark and largely stationary. The finding highlighted a collapse in maritime visibility amid escalating tensions.
After a May 4 attack on Fujairah-linked energy infrastructure, oil exports reportedly fell from typical levels of 3.5 to 4 million barrels per day to about 500,000. Windward linked the disruption to broader coordinated pressure on UAE-linked infrastructure.
Windward reported that the vessel MSC ISHYKA was struck by a drone while berthed in Bahrain. The attack illustrated that maritime risk had spread from transit lanes to port infrastructure.
Windward reported a missile strike on the tanker AQUA 1 in Qatari waters as kinetic risk expanded in the Gulf. The incident was cited alongside other attacks on vessels and port infrastructure during the conflict.
Windward reported a major operational shift from a single chokepoint to a dual-corridor system in the Strait of Hormuz. Between April 2 and April 5, a southern route along the Omani coastline expanded rapidly for coordinated multi-vessel transits while permissions remained selective.
Khaleej Times reported that activities at two Catholic churches in Dubai were suspended from April 3 until further notice. The move followed ongoing missile and drone threats and casualties in the UAE.
On day 35 of the war, UAE authorities publicly rejected an IRGC claim that Oracle's data center in Dubai had been attacked, calling it fake news. The denial came amid continued missile and drone exchanges and concern over attacks on economic targets.
Al Jazeera reported missile and drone strikes on a Kuwaiti power and desalination plant and on the Al-Ahmadi oil refinery. Kuwaiti authorities blamed Iran, while the IRGC denied responsibility and accused Israel.
Khaleej Times reported that UAE air defenses intercepted Iranian ballistic missiles and drones on April 2 amid widening regional spillover from the war. The same reporting tied the incident to broader GCC concerns over shipping security through the Strait of Hormuz.
AWS waived all March 2026 usage-related charges in the ME-CENTRAL-1 region after severe disruption tied to the reported Iranian drone strikes. The company also planned to remove March usage for that region from billing and cost-reporting tools.
Tom's Hardware reported that contractor Alcatel Submarine Networks declared force majeure because it could no longer safely operate in the Persian Gulf. This disrupted the unfinished Pearls segment of Meta's Africa2 cable project linking Gulf states, Pakistan, and India to Africa and Europe.
SC Media reported that Iran's Islamic Revolutionary Guard Corps had identified facilities associated with Google, Amazon, Oracle, IBM, and Nvidia in the Middle East as potential physical attack targets. Iranian messaging framed the threat as retaliation for alleged attacks on Iranian banking infrastructure and recent joint US-Israel strikes.
Cyberwarzone identifies a March 11 attack on Stryker as a clear example of Iran-linked retaliatory cyber disruption. The incident affected parts of Stryker's Microsoft environment and caused downstream impacts on ordering, manufacturing, and shipping.
Windward reported large-scale GPS jamming affecting roughly 1,100 ships in the Gulf, marking an early major electronic-warfare disruption to maritime navigation during the conflict. Later reporting described similar spoofing and AIS anomalies around the Strait of Hormuz and nearby waters.
Multiple references state that Iranian aerial attacks targeted AWS data center facilities in the UAE and Bahrain, causing significant cloud-service disruption in the Middle East. One report says two of three AWS ME-CENTRAL-1 availability zones were destroyed in the UAE region.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
foreignaffairs.com
Open sourcearstechnica.com
Open sourcetomshardware.com
Open sourcewindward.ai
Open sourcescworld.com
Open sourcescientificamerican.com
Open sourcecnn.com
Open sourcewindward.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.