On April 1, 2026, Iran's Islamic Revolutionary Guard Corps (IRGC) published a list of 18 technology companies it considers "hostile infrastructure" in the Persian Gulf. On the list: Apple, Google, Microsoft, Nvidia, Boeing, Tesla, and others. The threat encompasses physical attacks on data centers, undersea cables, and technology infrastructure in the Gulf region.
Why This Is Relevant
The Gulf region (Dubai, Abu Dhabi, Bahrain, Saudi Arabia) has developed into one of the fastest-growing cloud and AI hubs in the world in recent years:
- Microsoft: Azure data centers in Dubai and Abu Dhabi. Expansion to Saudi Arabia planned.
- Google: Cloud region in Doha (Qatar) since 2024. Dammam (Saudi Arabia) since 2025.
- AWS: UAE region since 2022. Second region in Saudi Arabia announced.
- Nvidia: Partnerships with Saudi sovereign wealth funds for AI data center infrastructure.
- Undersea Cables: Over 17 international undersea cables run through the Persian Gulf and the Red Sea. They carry an estimated 30% of European-Asian internet traffic.
Direct Impact on Europe
Even though the infrastructure is physically located in the Gulf region, European companies are affected:
- Latency and Routing: If undersea cables in the Persian Gulf are damaged, traffic is rerouted. Latencies to Asian services increase. In 2024, Houthi attacks in the Red Sea already caused cable damage with measurable effects.
- Cloud Availability: Companies with workloads in Azure UAE or Google Doha need to review failover strategies. Multi-region deployments become more important.
- Supply Chains: Chip shipments transported through the Persian Gulf could be delayed. This indirectly affects European manufacturing and IT procurement.
- Cyberattacks as Accompanying Action: Historically, Iran accompanies physical escalation with cyber operations. Iranian APT groups (APT33, APT35, MuddyWater) are known for attacks on Western IT infrastructure and critical sectors.
What IT Leaders Should Review Now
- Identify dependencies: Which cloud regions, CDN nodes, and SaaS services have infrastructure in the Gulf region? AWS, Azure, and Google offer region mapping in their dashboards.
- Test failover: If the UAE/Qatar region goes down, does failover automatically switch to a European region? Test it, do not assume it.
- Check cable redundancy: For companies with significant Asia traffic: Evaluate alternative routes via the northern route (Russia, problematic) or transpacific (US detour).
- Threat intelligence: Monitor Iranian APT activities. Integrate IOCs from CrowdStrike (Charming Kitten), Mandiant (APT35), and Microsoft (Peach Sandstorm) into SIEM rules.
- Update incident response: Include geopolitical escalation as a scenario in the IR plan. Communication channels, decision makers, failover procedures.
Geopolitics and IT infrastructure have never been so closely intertwined. The IRGC threat may currently be focused on the Gulf region. But in a connected world, the effects are global.
Sources: Defence Security Asia, Reuters, CrowdStrike Global Threat Report 2026, Submarine Cable Map (TeleGeography).