The Cloud Region Is Now a Military Target, and the Contract Doesn't Say So
Insurance and cloud agreements written for hurricanes carry act-of-war exclusions that a munitions strike triggers, and breach liability is steepening in Seoul and Brussels while Washington softens.
The clause that turns a strike into your loss
The paperwork matters more than the munitions here. Cloud master agreements and cyber policies carry act-of-war and physical-destruction exclusions written against storms, fires and fibre cuts. A strike on a Gulf facility triggers those, not service credits, and the loss sits with you while the reinsurer argues intent for a year. Region selection is a foreign-policy judgement now, and almost no availability-zone diagram scores it.
Risky Business, alone in today's set, reports Iran struck AWS facilities in Bahrain and the UAE twice in 2026, with threats extending to further US technology firms. One newsletter is thin ground for a claim that size, so confidence is medium. The contract exposure holds even if the count is wrong. The risk is not one region going dark. It is a correlated outage no disaster-recovery test has simulated, arriving with a diplomatic cause and no restore path. Two of the regions serving Europe, the Middle East and Africa sit inside that judgement.
Liability steepens in Seoul and Brussels, flattens in Washington
Korea's consumer agency ordered Coupang to compensate every affected user $70 across more than 37 million people, roughly $2.6 billion implied. Whether it is ever paid matters less than the template, and templates travel. US telcos and Republican lawmakers pushed an appellate rehearing to unwind the FCC's expanded breach rules, and it is ENISA, not CISA, publishing the secure-by-design playbook engineers can implement.
A skeptic would call alignment to the European baseline expensive theatre. A loss model calibrated to US notification norms under-invests in security engineering and under-reserves for liability at once. Aligning upward buys every market simultaneously, and part of the estate is already built that way.
The adversary spends everything for one token
Storm-2945, the Russian SVR subgroup Microsoft attributes this campaign to, spends heavily for one token. DNS hijacking at WiFi gateways, ClickFix lures, malware Microsoft names CornFlake RAT and CocoShell, the FruitStone command-and-control panel: all of it steals Entra device codes and OAuth tokens to bypass multi-factor authentication. Microsoft says gateways at "all sorts of organizations" were hit, not just hotels. The GRU's APT28 ran the same playbook through MikroTik and TP-Link routers. Convergence by two rival services is doctrine, and doctrine does not get taken down.
Disabling the device-code authentication flow is a conditional-access change measured in days, still enabled in most tenants, and it ends the payoff of a campaign running since May. Detection weighted to network and endpoint while identity telemetry goes unqueried leaves the vault open.
The lever the West held is eroding
The Information reports that China has moved to mass production of homegrown DUV lithography tools. Export controls at that node were the primary Western lever over Chinese fabrication capacity. Any three-year plan embedding constrained Chinese capacity is weaker than it looks, and that assumption hides in compute cost curves and in supplier moats. State capability is now setting variables procurement has treated as fixed.
What to do
Direct the CISO to disable OAuth device-code authentication tenant-wide via conditional access as a priority action, and require compliant-device checks for all token issuance.
Commission a geopolitical region-risk review with the GC this quarter that strips act-of-war and physical-destruction exclusions out of cloud and insurance contracts before renewal.
Re-underwrite breach loss estimates by jurisdiction against the Korean compensation order and brief the audit committee this quarter on divergence from the softening US baseline.